CVE-2017-12286
published 2017-10-19CVE-2017-12286: A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected…
PriorityP426medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.36%
27.9th percentile
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vulnerability by authenticating locally to an affected system and then issuing specific commands to the affected software. A successful exploit could allow the attacker to view all profile information for a user instead of only certain Jabber parameters that should be visible. This vulnerability affects all releases of Cisco Jabber prior to Release 1.9.31. Cisco Bug IDs: CSCve52418.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | jabber | — | — |
| cisco | webex_meeting_center | — | — |
| cisco | webex_messenger | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_cisco5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w3mp-fvv7-2gpv: A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affect
ghsa_unreviewed·2022-05-13
CVE-2017-12286 [MEDIUM] CWE-20 GHSA-w3mp-fvv7-2gpv: A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affect
A vulnerability in the web interface of Cisco Jabber could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vulnerability by authenticating locally to an affected system and then issuing specific commands to the affected software. A successful exploit could allow the attacker to view all profile information for a user instead of only certain Jabber parameters that should be visible. This vulnerability affects all releases of Cisco Jabber prior to Release 1.9.31. Cisco Bug IDs: CSCve52418.
Cisco
Cisco Webex Messenger Information Disclosure Vulnerability
vendor_cisco·2017-10-18·CVSS 5.5
CVE-2017-12286 [MEDIUM] CWE-20 Cisco Webex Messenger Information Disclosure Vulnerability
Cisco Webex Messenger Information Disclosure Vulnerability
A vulnerability in the web interface of Cisco Webex Messenger could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information.
The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vulnerability by authenticating locally to an affected system and then issuing specific commands to the affected software. A successful exploit could allow the attacker to view all profile information for a user instead of only certain Webex Messenger parameters that should be visible.
There are no workarounds that address this vulnerability.
This advisory is available at the
Cisco
Cisco Webex Messenger Information Disclosure Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-12286 Cisco Webex Messenger Information Disclosure Vulnerability
CVE-2017-12286: Cisco Webex Messenger Information Disclosure Vulnerability
A vulnerability in the web interface of Cisco Webex Messenger could allow an authenticated, local attacker to retrieve user profile information from the affected software, which could lead to the disclosure of confidential information. The vulnerability is due to a lack of input and validation checks in the affected software. An attacker could exploit this vulnerability by authenticating locally to an affected system and then issuing specific commands to the affected software. A successful exploit could allow the attacker to view all profile information for a user instead of only certain Webex Messenger parameters that should be visible. There are no
CVSS: 3.0
CWE: CWE-20, CWE-20
Bug IDs: CSCve52418
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/101515http://www.securitytracker.com/id/1039625https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-jab1http://www.securityfocus.com/bid/101515http://www.securitytracker.com/id/1039625https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20171018-jab1
2017-10-19
Published